Security & Trust

Diligence data deserves
diligence-grade security.

Zoe handles some of the most sensitive data a company has — org charts, decision flows, internal communication patterns. Here’s exactly how we protect it.

Security Pillars

How we protect diligence data.

The security pillars that govern how Zoe collects, processes, and stores every byte of customer data.

Pillar 01

Encryption everywhere

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Keys are managed in dedicated KMS instances with automated rotation. No exceptions.

Pillar 02

Least-privilege access

Role-based access controls with SSO and full audit logs. Diligence data is scoped per engagement and expires on a fixed schedule. No standing access.

Pillar 03

Isolated tenancy

Each engagement runs in its own workspace with dedicated encryption keys. No cross-tenant data sharing, ever. Isolation is enforced at the storage layer, not in code.

Pillar 04

Minimal data collection

Zoe collects only the aggregate metadata required to compute the diagnostic. From live systems it never reads message bodies, code, or financial line items, and personal identifiers are stripped at ingestion. Documents you upload to the data room are read as cited evidence. Source data can be purged immediately on request.

Pillar 05

Compliance posture

Working toward SOC 2 Type II. GDPR- and CCPA-aligned data handling. NDA and DPA available on request. (Formal certification status shared under NDA.)

Pillar 06

Responsible disclosure

Found a vulnerability? Email security@zoediagnostics.com. We respond within 24 hours and credit researchers in our public hall of fame.

Pillar 07

Codename privacy

Running diligence on a live target? The real company name is encrypted at rest, revealed only on hover, and never written into the page source — and a screen-share-safe mode hides it entirely. Public IC and LP share links strip the real name and your workspace ID. Recipients see only the codename.

Pillar 08

Aggregate-only, PII stripped

Personal identifiers — names, emails, @-mentions — are removed at the ingestion boundary before any sentiment scoring. The model never sees who said what. Team and culture signals are read in aggregate, never an individual.

Pillar 09

Authentication & isolation

Two-factor authentication (TOTP) with 30-day trusted devices and instant session revocation. Every record is scoped to its workspace, every API route is authenticated and rate-limited, and an audit log is written on every response.

Pillar 10

Trustworthy AI answers

Ask Zoe labels every answer by how much to trust it — computed, sourced, judged, or generated — shows the calculation behind any number, and refuses when the evidence is thin. Flag any answer and Zoe routes it to review and tracks its own accuracy.

Data Flow

Source data in.
Scores out.

Raw metadata enters an isolated processing workspace, gets transformed into anonymized signal, contributes to the nine-dimension scoring engine, then is discarded.

Only the resulting scores, findings, and aggregated patterns persist after the report ships. The raw data never survives the engagement. This isn’t a policy — it’s how the system is built.

Engagement Data Flow
1
Source data
QuickBooks, HubSpot, Slack, GitHub, data room — read-only
2
Isolated processing
Per-engagement workspace, dedicated encryption key
3
Discard raw data
Source data purged after scoring completes
4
Persist only scores
Findings + aggregated patterns retained inside scoped workspace
Compliance

Where we are with each framework.

Honest status, not marketing-speak. We’re building toward enterprise compliance and we’ll tell you exactly where each piece stands.

SOC 2 Type II
In progress
Independent audit underway; current status shared under NDA.
GDPR
Aligned
EU-aligned data handling, right to erasure, DPAs available on request.
CCPA
Aligned
California-aligned data subject rights and deletion workflows.
HIPAA
Roadmap
Healthcare-specific controls are on the roadmap; no BAA available today.
Need More Detail?

Request our security questionnaire.

Same-day delivery of our full security questionnaire, NDA, and DPA. We’ve been through enterprise procurement before.

Join 200+ firms on the waitlist